PRIVACY NOTICE · 2026-08-09-draft

Verify the fact, not the whole person.

AstruVerify is designed to minimise identity data: a requesting organisation asks for specific facts, the citizen sees the request, and an identity provider verifies approved facts without AstruVerify collecting biometric templates or bank credentials.

Proof-of-concept: this notice describes the intended AstruVerify operating model. Before LIVE processing, the responsible party, Information Officer, PAIA manual and final legal wording must be completed and professionally reviewed.

Responsible party

AstruVerify operator (configure before LIVE)

Information Officer: Not configured yet
Privacy contact: privacy@astruverify.com

What AstruVerify processes

Account details, verification-request metadata, claim names, consent receipts, provider/method metadata, short-lived signed assertions, security/audit events and privacy-request records.

AstruVerify is designed not to collect bank passwords, bank PINs, fingerprint templates, face templates, balances or transaction histories.

Why it processes data

To authenticate accounts, route identity-verification requests, record citizen decisions, issue limited signed assertions, protect the service, maintain audit evidence and respond to privacy-rights requests.

Notice at collection

Before a citizen approves identity claims, AstruVerify displays the requesting organisation, the stated purpose, the exact claims requested, the selected identity provider, and whether standing consent is being offered. Consent choices are recorded as a receipt.

Where processing relies on a basis other than consent, that basis must be identified and documented by the responsible party before LIVE use. AstruVerify does not treat a consent checkbox as a universal legal basis for every processing activity.

Retention and minimisation

Portable assertion payloads are short-lived and removed after their configured retention window. Older completed verification records are de-linked from citizen and organisation accounts, and operational logs use separate retention periods.

Signed-in citizens can view What AstruVerify stores about me.

Your privacy controls

Signed-in citizens can obtain a self-service export and submit requests for access/export, correction, deletion/destruction or objection to processing.

Security compromises

AstruVerify maintains an internal incident register so administrators can document detection, containment, affected information, notification assessment, and when notifications to the Information Regulator or affected data subjects were made. The software records the decision; it does not decide the legal obligation automatically.